D2IT Governance

IT Governance: Exam Day Guide

Time Management for Domain 2 Questions

Domain 2 represents 17% of the exam, yielding approximately 26 questions. Governance questions tend to be conceptual rather than technical, so many can be answered in under a minute if you know the frameworks well. However, scenario-based governance questions that describe organizational structures or decision-making processes may require careful reading. Budget roughly 90 seconds per question and use any time saved on straightforward framework questions to invest in more complex risk management scenarios.

Approaching Governance Scenario Questions

Governance scenarios often describe an organization with a specific structure and ask you to identify gaps or recommend improvements. Always look for whether the scenario describes a separation of duties issue, a missing oversight function, or an accountability gap. ISACA expects answers that align IT governance with business objectives; any answer that treats IT as a standalone function rather than a business enabler is likely wrong. Consider which governance body (board, steering committee, IT management) is responsible for the activity described.

Key Patterns to Recognize

COBIT principles appear frequently, so understand the distinction between governance (evaluate, direct, monitor) and management (plan, build, run, monitor) processes. When a question references IT strategy, the correct answer will connect IT initiatives to business goals through mechanisms like balanced scorecards or IT steering committees. Risk management questions follow a consistent pattern: identify, assess, respond, monitor. Recognize that risk appetite is set by the board while risk tolerance is the acceptable variation from that appetite.

Common Trap Answers

A common trap in governance questions is selecting an answer that assigns responsibility to the wrong level of the organization. For example, the board sets strategic direction but does not manage day-to-day IT operations. Another trap involves confusing IT governance frameworks; COBIT is a governance framework, ITIL is a service management framework, and ISO 27001 is an information security management standard. Watch for answers that suggest technology solutions when the question is asking about governance processes or organizational structures.

What ISACA Expects as the Best Answer

ISACA consistently favors answers that demonstrate alignment between IT and business objectives, proper assignment of accountability, and measurable performance outcomes. The best answer in governance questions is the one that ensures oversight, transparency, and value delivery from IT investments. When evaluating risk management options, ISACA prefers a balanced approach that considers both the likelihood and impact of risks rather than simply avoiding all risk. Compliance with regulatory requirements is always a baseline expectation, not a best practice.

Vendor and Third-Party Management

Questions about vendor management will test your understanding of the full vendor lifecycle, from selection and due diligence through contract management and performance monitoring to termination. The right to audit clause is a critical contract element that ISACA expects you to recognize. When a scenario describes outsourcing, remember that the organization retains accountability for outsourced activities even though operational responsibility may transfer to the vendor. SLA monitoring and regular vendor assessments are essential governance controls.

Data Governance and Compliance

Data governance questions focus on data ownership, classification, and lifecycle management. The data owner (typically a business manager) is responsible for classifying data and approving access, while the data custodian (typically IT) implements the technical controls. Privacy regulations and cross-border data transfer requirements are increasingly tested topics. Remember that data retention policies must balance business needs, legal requirements, and storage costs.

Practical Exam Day Logistics

Use the first few minutes of the exam to take a deep breath and read the tutorial screens carefully, even if you have taken computer-based exams before. The PSI testing interface allows you to flag questions for review; use this feature strategically for governance questions where two answers seem equally plausible. Write down key framework distinctions (COBIT vs. ITIL vs. ISO 27001) on your provided notepad immediately, as this will save time when answering framework-specific questions. Stay hydrated before the exam, as dehydration affects concentration and decision-making.